7.5
CVSSv2

CVE-2002-0319

Published: 25/06/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting vulnerability in edituser.php for pforum 1.14 and previous versions allows remote malicious users to execute script and steal cookies from other users via Javascript in a username.

Vulnerable Product Search on Vulmon Subscribe to Product

powie pforum 1.12

powie pforum 1.13

powie pforum 1.14

powie pforum 1.11

Exploits

source: wwwsecurityfocuscom/bid/4165/info Powie PForum is web forum software, written in PHP and back-ended by MySQL It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems PForum is prone to cross-site scripting attacks It is possible for an attacker to construct a malicious link which includes arb ...